Project Zomboid: Security and Anti-Cheat for Dedicated Servers
Managing a public Project Zomboid dedicated server requires more than just performance tuning. With the rise of "griefing" scripts and cheat clients in 2026, server administrators must utilize the full suite of built-in anti-cheat tools and external security measures provided by their hosting service.
🚫 Anti-Cheat Hooks
Build 42 ships ten named AntiCheat checks, each set independently to ban, kick, log or disabled. They cover speed hacks, item spawning, XP manipulation and safehouse exploits. The numbered 1-24 scheme was a Build 41 thing and is gone.
📝 Whitelisting
The most effective way to prevent mass-griefing is to require a password or unique Steam ID registration before joining.
Does Project Zomboid Have Anti-Cheat?
Yes. Build 42 ships ten separate anti-cheat checks, each set independently, plus a Lua checksum. Eight of the ten are on by default.
If you are following an older guide: AntiCheatProtectionType1 through AntiCheatProtectionType20 were the Build 41 names. Build 42 replaced the whole numbered set with the ten named options below. There is no VerifyUsername setting in Build 42 either.
The Ten Anti-Cheat Settings
Each takes a number, not true or false:
| Value | Effect |
|---|---|
1 | ban |
2 | kick |
3 | log only |
4 | disabled |
| Setting | Protects against | Default |
|---|---|---|
AntiCheatSafety | Safety system tampering | 2, kick |
AntiCheatSpeed | Character speed hacks | 2, kick |
AntiCheatHit | Character hit manipulation | 2, kick |
AntiCheatPermission | Player permission escalation | 2, kick |
AntiCheatXP | Player XP manipulation | 2, kick |
AntiCheatSafeHouse | Safehouse exploits | 2, kick |
AntiCheatPlayer | General player checks | 2, kick |
AntiCheatChecksum | Checksum tampering | 2, kick |
AntiCheatNoClip | Character no-clipping | 4, disabled |
AntiCheatPacketException | Packet exception checks | 4, disabled |
The last two ship disabled, not merely lenient. If you want no-clip and packet checks enforced, set them yourself.
Turning Anti-Cheat Off
Modded servers trip the checks, which is the usual reason to reach for this. Set the specific one to 4 rather than disabling everything:
AntiCheatNoClip=4
AntiCheatSpeed=4
Prefer 3 (log only) first. It records the same detections without kicking anyone, so you can see whether a mod really is the cause before you switch a protection off for good.
DoLuaChecksum
DoLuaChecksum is a separate boolean, default true. It kicks clients whose game files do not match the server's. It is what produces the mismatch error below, and it is the setting to look at when a mod update leaves players unable to connect.
Dealing with "Checksum" Errors
One of the most common dedicated server complaints is the "File doesn't match the server" error. This is actually a security feature. If your players encounter this:
- Ensure the server mod list matches the client exactly.
- Ask players to delete their
/Zomboid/Saves/Multiplayer/folder to clear cached data. - Check the
steam_dedicated_idto ensure the server has updated to the latest build.
Admin Security Best Practices
Never share your admin password via Discord or chat. Use the hosting panel to grant specific "Moderator" or "Admin" roles to players via their Steam IDs. This allows you to track actions in the logs and revoke access without changing the global server password.
Security Tip: Use a dedicated server with automatic backups. Even with the best anti-cheat, a determined griefer can burn down a base. Having a 1-click restore to a state 2 hours ago is your final line of defense.
Secure Project Zomboid Hosting
Sleep easy knowing your survivor's world is protected. At Supercraft, our Project Zomboid hosting includes hardened firewalls, automated backup systems, and a managed anti-cheat installer that configures all settings for maximum security without breaking your mods.